Privacy Policy
Privacy Policy
Privacy Policy for the B2C online store “CapUniverse” operated by ANTHEC GmbH & Co. KG. Protecting your personal data is important to us. This Privacy Policy explains which personal data we process when you use our online store, the purposes for which we process it and the rights available to you.
1. Controller and Data Protection Officer
Controller:
ANTHEC GmbH & Co. KG
Willy-Brandt-Weg 36
48155 Münster
Germany
Telephone: 0800 22777467
Email: datenschutz@capuniverse.com
External Data Protection Officer:
Markus Weber
dokuworks GmbH
Essener Str. 1
57234 Wilnsdorf
Germany
Email: datenschutz@doku.works
2. General Information and Legal Bases
Personal data means any information relating to an identified or identifiable natural person. We process personal data only where there is a legal basis for doing so.
Depending on the processing activity, we rely in particular on:
- Art. 6(1)(a) GDPR where you have given your consent,
- Art. 6(1)(b) GDPR for steps taken before entering into a contract and for performance of a contract,
- Art. 6(1)(c) GDPR for compliance with legal obligations, and
- Art. 6(1)(f) GDPR for our legitimate interests or those of a third party, provided that your interests or fundamental rights do not override those interests.
The storage of information on your device or access to information already stored on it is also governed by Section 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG). As a rule, we use cookies and similar technologies that are not technically necessary only with your consent.
3. Accessing the Online Store and Server Log Files
When you access our online store, your browser automatically transmits technical information. This may include your IP address, date and time of access, the page or file requested, referrer URL, browser type and version, operating system, language settings and internet service provider.
We process this information to provide the website, ensure secure and stable operation, detect errors and prevent misuse. The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in operating our online store securely and reliably. Log data is deleted as soon as it is no longer required for these purposes, unless longer retention is necessary to investigate a security incident.
4. Shopify, Hosting and Cloudflare
Our online store is operated using the Shopify e-commerce platform. The provider for users in the European Economic Area is Shopify International Limited, 2nd Floor, Victoria Buildings, 1–2 Haddington Road, Dublin 4, D04 XN32, Ireland.
On our behalf, Shopify processes in particular master data, contact details, order and payment data, device and usage data and log data where this is required to operate the store, process orders, prevent fraud, perform analytics and provide customer accounts. Depending on the Shopify feature used, Shopify may also process certain data under its own responsibility.
The legal bases are Art. 6(1)(b) GDPR for entering into and performing contracts and Art. 6(1)(f) GDPR for the secure, commercially viable and user-friendly operation of our online store. Where Shopify or services integrated through Shopify use non-essential analytics, marketing or personalisation features, processing is based on your consent in accordance with Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
For load balancing, content delivery and protection against attacks, Shopify uses Cloudflare, Inc., USA, among other subprocessors. In this context, IP addresses, connection data and device information in particular may be processed.
Further information is available in Shopify’s Privacy Policy and the Shopify Consumer Privacy Policy.
5. Orders, Customer Accounts and Contacting Us
Orders
When you place an order, we process in particular your name, billing and delivery address, email address, telephone number, items ordered, order and payment information and any other information you provide. Processing is carried out to manage your order, deliver the goods, communicate with you, handle returns and warranty claims and prevent fraud. The legal basis is Art. 6(1)(b) GDPR. We retain documents relevant for tax and commercial-law purposes for the statutory retention periods in accordance with Art. 6(1)(c) GDPR.
Customer Account
If you create a customer account, we process your registration details, contact details and order data to provide and manage the account. The legal basis is Art. 6(1)(b) GDPR. You may request deletion of your customer account unless statutory retention obligations require us to keep certain data.
Contacting Us
If you contact us by email, telephone or contact form, we process your contact details and the content of your enquiry in order to respond. The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract and otherwise Art. 6(1)(f) GDPR. Our legitimate interest lies in handling enquiries properly.
Product Reviews
If you submit a product review, we process the information you provide, your chosen display name and the date and time of the review. This processing is necessary to publish and manage the review and to protect against abusive or unlawful content. The legal bases are Art. 6(1)(b) and (f) GDPR.
6. Cookies and Consent Management
We use cookies and similar technologies. Strictly necessary cookies enable functions such as the shopping basket, login, language settings, payment processing, security and storage of your privacy preferences. They are used on the basis of Section 25(2) TDDDG and Art. 6(1)(b) or (f) GDPR.
Analytics, marketing and personalisation technologies are generally used only after you have given your consent. The legal bases are Section 25(1) TDDDG and Art. 6(1)(a) GDPR. You can change or withdraw your consent at any time with future effect through the store’s cookie settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7. Newsletter and Email Marketing
Newsletter via rapidmail
We use rapidmail to send and analyse our newsletter. The provider is Positive Group Deutschland GmbH, Ingeborg-Krummer-Schroth-Straße 18a, 79106 Freiburg im Breisgau, Germany.
If you subscribe to our newsletter, we process in particular your email address and records of your registration and confirmation. Registration uses a double opt-in process. rapidmail may also record whether a newsletter has been opened and which links have been clicked. Tracking pixels and personalised links may be used for this purpose.
The legal basis for sending and analysing the newsletter is your consent under Art. 6(1)(a) GDPR. You can withdraw your consent at any time by using the unsubscribe link in each message or by contacting us. After you unsubscribe, we delete your newsletter data unless legal evidentiary or retention obligations require otherwise. We may retain the information needed to demonstrate that consent was given until the applicable limitation periods have expired.
We have entered into a data processing agreement with rapidmail. According to the provider, newsletter data is stored in Germany. Further information is available in rapidmail’s Privacy Policy.
Product Recommendations to Existing Customers
Where we use an email address received in connection with a purchase to advertise our own similar goods or services, we do so subject to the requirements of Section 7(3) of the German Act Against Unfair Competition (UWG) and on the basis of our legitimate interest in direct marketing under Art. 6(1)(f) GDPR. You may object to this use at any time free of charge, for example by using the unsubscribe link in the relevant email or by contacting us.
8. Payment Processing
Shopify Payments
We primarily use Shopify Payments to process payments. Depending on the payment method selected, payment data, name, billing address, email address, IP address, device information and transaction data may be transmitted to Shopify and the payment processor used for the transaction. Under the Shopify Payments terms applicable in Germany, these may include Stripe Payments Europe, Ltd., PayPal (Europe) S.à r.l. et Cie, S.C.A. or Adyen N.V.
Processing is carried out to manage the payment and contractual relationship under Art. 6(1)(b) GDPR, comply with legal obligations and prevent fraud under Art. 6(1)(c) and (f) GDPR. Individual payment providers may process certain data under their own responsibility.
PayPal
If you select PayPal as a separate payment method, the data required to process the payment is transmitted to PayPal (Europe) S.à r.l. et Cie, S.C.A., 22–24 Boulevard Royal, L-2449 Luxembourg. PayPal may process additional information for identity and credit checks and fraud prevention and may involve credit reference agencies. The legal basis for the transfer is Art. 6(1)(b) GDPR. Further information is available in PayPal’s Privacy Statement.
Digital Wallets
If you choose Shop Pay, Apple Pay or Google Pay, the relevant provider processes the data required to provide the selected payment method. The privacy notices and terms of use of the relevant provider also apply. The legal basis is Art. 6(1)(b) GDPR.
9. Delivery Service Providers
To deliver your order, we transmit the required data, in particular your name, delivery address and, where applicable, contact details, to the selected delivery service provider. The transfer is necessary for performance of the contract under Art. 6(1)(b) GDPR. Where you expressly consent to the transfer of your email address or telephone number for parcel notifications or delivery scheduling, the legal basis is Art. 6(1)(a) GDPR.
10. Protection of Forms Using hCaptcha
Shopify uses hCaptcha to protect contact, newsletter, comment and customer-account forms against automated access, spam and misuse. The provider is Intuition Machines, Inc., USA.
hCaptcha analyses technical and behavioural information to determine whether an entry is made by a person or an automated program. This may include the IP address, device and browser information, mouse movements, input behaviour, the page accessed and the date and time.
The processing serves to protect our online store and its users. The legal basis is Art. 6(1)(f) GDPR and, where access to information on the device is strictly necessary, Section 25(2) TDDDG. Our legitimate interest lies in preventing spam, fraud and automated attacks. Further information is available in hCaptcha’s Privacy Policy.
11. Wishlist Feature Provided by Swym
We use “Wishlist Plus” by Swym Corporation, USA, for our wishlist feature. If you use the wishlist, product and wishlist data, device and browser information, IP address, usage data and – for logged-in customers – contact details may be processed.
Processing is carried out to provide the wishlist feature requested by you under Art. 6(1)(b) GDPR. Where Swym processes data for analytics, marketing or personalisation or uses non-essential technologies, this takes place only with your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Further information is available at https://swym.it/privacy/.
12. Virtual Try-On
Our website offers an optional AI-powered virtual try-on feature. You can use your device’s camera to take a photo or select an existing photo. Use of the virtual try-on is voluntary. You can use our online store without this feature.
To create the virtual preview, we process the photo you take or select, information about the selected headwear and the resulting preview image. The AI analyses visible features and the proportions of your head and face to the extent necessary to position the headwear in the image.
The data is transmitted to our technical service provider and processor, Google Cloud EMEA Limited, 70 Sir John Rogerson’s Quay, Dublin 2, Ireland, and processed using the Google Gemini AI service. Under the paid service we use, Google does not use the submitted images or generated results to train or generally improve its AI models.
Neither we nor Google acting on our instructions use the image data to identify or verify you. No biometric identification profile is created. The data is not used for advertising, customer profiling, creditworthiness assessments or purchasing decisions. No automated decision-making with legal or similarly significant effects within the meaning of Art. 22 GDPR takes place.
We process the photo to provide the virtual try-on that you have expressly requested and to assist with your potential purchasing decision. The legal basis is Art. 6(1)(b) GDPR for steps taken at your request before entering into a contract. You make this request by opening the virtual try-on and deliberately taking or selecting a photo.
On our systems, the original photo and the generated preview are processed only temporarily to provide the virtual try-on. They are not permanently linked to a customer account, order or other customer profile and are deleted as soon as they are no longer technically required for the current try-on session.
Google carries out automated security checks and retains the inputs submitted to the Gemini API and the generated outputs for up to 55 days to detect violations of its usage policies and prevent misuse. If a security-related issue is detected, appropriately authorised Google personnel may review the affected content. The data is used solely to enforce the usage policies and prevent misuse. The legal basis for this processing is Art. 6(1)(f) GDPR. Our legitimate interest lies in operating the feature securely and in accordance with the applicable terms and in preventing misuse.
Google may also process data outside the European Economic Area, particularly in the United States. For transfers to appropriately certified US companies, Google relies on the EU-US Data Privacy Framework. Where this framework does not apply, the standard contractual clauses approved by the European Commission are used.
Please use only a photo of yourself that does not show any other person. The virtual try-on is intended for persons aged 18 or over.
Further information is available in the Gemini API Terms, the information on abuse monitoring and Google’s Data Processing Terms.
13. Analytics and Marketing Services
As a rule, we use the analytics and marketing services described below only if you have consented through our consent-management system. The legal bases are Art. 6(1)(a) GDPR and Section 25(1) TDDDG. You can withdraw your consent at any time through the cookie settings.
Google Tag Manager
We use Google Tag Manager provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Tag Manager is used to manage and trigger other analytics and marketing tags. It generally does not create its own user profiles, but it may process technical data such as the IP address and establish connections to Google. Any additional data processed depends on the services integrated through Tag Manager.
Google Analytics 4
We use Google Analytics 4 provided by Google Ireland Limited to analyse use of our online store and improve our offering. Data processed may include page views, interactions, order and conversion events, approximate location, device and browser information, referrer URL and pseudonymous identifiers. We use Google Analytics with the privacy and consent features provided by Google.
The retention period for event and user data that we can configure depends on the settings selected in Google Analytics. Aggregated reports may be retained for longer. Further information is available at https://policies.google.com/privacy.
Google Ads and Conversion Tracking
We use Google Ads, including conversion and remarketing features. This allows us to determine whether users perform certain actions after clicking an advert and to display interest-based advertising. Data processed may include cookie or device identifiers, IP address, pages accessed, interactions and order and conversion data. The recipient is Google Ireland Limited; processing by Google LLC and other group companies cannot be ruled out.
Meta Pixel
We use the Meta Pixel provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland. This enables us to measure the effectiveness of advertising on Facebook and Instagram and create advertising audiences. Data processed may include page views, interactions, purchases, shopping-basket and conversion data, IP address, device information and cookie and advertising identifiers. If you are logged in to Meta, Meta may associate the data with your account.
Further information is available at https://www.facebook.com/privacy/policy/.
TikTok Pixel
We use the TikTok Pixel provided by TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland. The pixel is used to measure and optimise our advertising on TikTok and create advertising audiences. Data processed may include IP address, device and browser information, page views, interactions, shopping-basket and order data and cookie and advertising identifiers. If you use TikTok, TikTok may associate the data with your account.
Further information is available at https://www.tiktok.com/legal/page/eea/privacy-policy/en.
Microsoft Advertising
We use Microsoft Advertising, including Universal Event Tracking (UET), provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. This allows us to determine whether users perform certain actions after clicking a Microsoft advert and to create advertising audiences. Data processed may include IP address, device and browser information, page views, interactions and order and conversion data.
Further information is available at https://privacy.microsoft.com/en-gb/privacystatement.
Awin Affiliate Marketing
We participate in the affiliate network operated by AWIN AG, Otto-Ostrowski-Straße 1A, 10249 Berlin, Germany. If you reach our store through an affiliate link, Awin and the referring publisher may recognise that a visit or purchase was referred. Pseudonymous click and transaction identifiers, IP address, device information, referrer, time, order value, product information and voucher data may be processed. Processing is used to attribute referrals and calculate commission payments.
Where cookies or similar technologies are used for this purpose, processing is based on your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG. Further information is available in Awin’s Privacy Policy.
Multifeed Google Shopping Feed
We use a Shopify app provided by Multi Feeds Limited to create and optimise product feeds and, where enabled, measure conversions for connected advertising platforms. Product, store, device, usage and conversion data may be processed. Where personal data is processed for analytics or marketing purposes or non-essential technologies are used, this takes place only with your consent under Art. 6(1)(a) GDPR and Section 25(1) TDDDG.
14. Social Media Profiles and External Links
Our online store may contain links to our profiles on social networks. Simply accessing our online store does not transmit data to the relevant network through a standard external link. Only when you click the link or activate embedded content after giving your consent will the provider receive information such as your IP address and the page from which you arrived. If you are logged in to the provider, it may associate the visit with your account. The relevant platform operator is responsible for any further processing.
15. Recipients and International Data Transfers
We disclose personal data only where necessary for the purposes described. Recipients may include hosting and platform providers, payment and delivery service providers, IT service providers, newsletter providers, analytics and advertising partners, tax advisers, public authorities and other parties to whom we are legally or contractually required to disclose data.
Some providers or their subprocessors are located outside the European Economic Area, particularly in the USA and Canada. Data is transferred only where the requirements of Art. 44 et seq. GDPR are met. Relevant safeguards may include an adequacy decision by the European Commission, in particular the EU-US Data Privacy Framework, or EU standard contractual clauses together with supplementary measures.
16. Retention Periods
We retain personal data only for as long as it is required for the relevant purpose. It is then deleted or anonymised unless statutory retention obligations, legitimate evidentiary interests or the establishment, exercise or defence of legal claims require longer retention. We retain commercial and tax documents for the applicable statutory periods. Records of consent may be retained until the relevant limitation periods have expired.
17. Your Rights
Subject to the applicable legal requirements, you have in particular the right to:
- obtain access to your personal data (Art. 15 GDPR),
- have inaccurate data corrected or incomplete data completed (Art. 16 GDPR),
- request deletion of your data (Art. 17 GDPR),
- request restriction of processing (Art. 18 GDPR),
- receive data you have provided in a structured, commonly used and machine-readable format or have it transmitted to another controller (Art. 20 GDPR),
- object to processing based on legitimate interests (Art. 21 GDPR), and
- withdraw consent at any time with future effect (Art. 7(3) GDPR).
To exercise your rights, contact datenschutz@capuniverse.com or our Data Protection Officer.
You also have the right to lodge a complaint with a data protection supervisory authority, in particular the authority in your habitual place of residence, place of work or the place of the alleged infringement. The authority responsible for our registered office is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de.
18. Right to Object to Direct Marketing
Where we process your personal data on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. You may object to the processing of your data for direct-marketing purposes at any time without giving reasons. Following your objection, we will no longer use the relevant data for direct marketing.
19. Data Security
We take appropriate technical and organisational measures to protect personal data against loss, manipulation, unauthorised access and other misuse. Data transmitted between your browser and our online store is encrypted. We review and update our security measures in line with technological developments.